Where Article 50 sits in the Act
Most of the EU AI Act is organised around risk: prohibited, high-risk, limited, minimal. Article 50 cuts across that structure. It imposes 'specific transparency obligations' that attach to particular kinds of AI regardless of their risk tier — a perfectly low-risk chatbot or image generator can be squarely in scope. The unifying idea is honesty about provenance: people should know when they are dealing with a machine, and when content they are looking at was made or altered by one.
The obligations apply from 2 August 2026. They used to share that date with the bulk of the high-risk regime; Regulation (EU) 2026/1744 deferred high-risk to 2 December 2027 and left Article 50 exactly where it was, which is why transparency is now the live obligation and high-risk is the one with runway. Article 50 is written in four operative paragraphs, and it splits its duties between providers (who build the disclosure into the system) and deployers (who switch it on and disclose in context). Getting the provider/deployer split right is half the work.
- •Article 50(1) — AI-interaction disclosure (provider duty).
- •Article 50(2) — machine-readable marking of synthetic content (provider duty).
- •Article 50(3) — emotion-recognition / biometric-categorisation notice (deployer duty).
- •Article 50(4) — deepfake and public-interest-text disclosure (deployer duty).
Article 50(1): tell people they are talking to an AI
Providers must ensure that AI systems intended to interact directly with natural persons are designed and developed so that the people concerned are informed that they are interacting with an AI system. This is the chatbot and voice-assistant rule. The disclosure is not required where it is obvious from the point of view of a reasonably well-informed, observant and circumspect person, taking account of the circumstances and context — and there is a narrow exception for systems authorised by law to detect, prevent or investigate criminal offences.
In practice the 'obvious' get-out is thinner than teams hope. A support widget on your website that answers in fluent prose is not obviously a bot to an ordinary user, so the safe reading is to disclose. The information must be given at the latest at the point of first interaction, clearly and distinguishably.
Article 50(2): mark synthetic content as artificially generated
Providers of AI systems — including general-purpose AI systems — that generate synthetic audio, image, video or text must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solutions must be effective, interoperable, robust and reliable as far as is technically feasible, taking account of the specificities and limitations of different content types. This is the watermarking and provenance-metadata obligation, and it is a provider duty on the generative system.
There are sensible limits. The duty does not bite where the AI performs a purely assistive function for standard editing, or where it does not substantially alter the input data supplied by the deployer — a grammar corrector is not producing a 'deepfake'. As with 50(1), there is a law-enforcement carve-out.
Article 50(3): notice for emotion recognition and biometric categorisation
Deployers of an emotion-recognition system or a biometric-categorisation system must inform the natural persons exposed to it of the operation of the system, and must process any personal data in line with the GDPR and related law. This is a deployer duty, in context, at the point of exposure. Where such use is permitted by law for criminal-offence purposes, the specific safeguards of that regime apply instead.
The practical trigger is exposure, not consent: if your premises or product run emotion recognition or sort people into biometric categories, the people affected have to be told it is happening.
Article 50(4): deepfakes and public-interest text
Article 50(4) carries two distinct deployer duties, and both come with carve-outs that matter.
Deepfakes
Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake must disclose that the content has been artificially generated or manipulated. The important exception is the artistic one: where the content is part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the obligation is limited to disclosing the existence of the generation in an appropriate manner that does not hamper the display or enjoyment of the work. A caption in the credits, not a watermark across the frame.
AI-generated text on matters of public interest
Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest must disclose that the text has been artificially generated or manipulated. Here the carve-out is editorial: the duty does not apply where the AI-generated content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication. In other words, a newsroom that runs an AI draft past a human editor who owns the piece is outside this specific duty — an automated feed that publishes unreviewed AI copy is not.
- •Deepfake disclosure has an artistic/creative/satirical exception — disclose, but without hampering the work.
- •Public-interest AI text has an editorial-responsibility carve-out — human review plus a named editor holding responsibility takes it out of scope.
- •Neither carve-out touches the machine-readable marking duty on the generative provider under Article 50(2).
How this interacts with GPAI marking
There is a natural overlap between Article 50(2) and the general-purpose AI regime. The model that actually produces the synthetic output is usually a GPAI model, and the machine-readable marking has to be built into the generation itself. If you are a downstream SME shipping a product on top of a foundation model, the model provider's watermarking and provenance tooling is what makes your outputs detectable — but the Article 50(2) obligation to mark still sits on you as the provider of the generative system.
The practical consequence: when you choose a generative model or API, ask what marking it supports (C2PA-style content credentials, provenance metadata, watermarking) and treat that as a compliance input, not just a feature. You are relying on the upstream marking to satisfy a duty the Act places on your own system.
Practical labelling steps for an SME
You do not need a large programme to meet Article 50 — you need three concrete things, documented so you can show them:
- Chatbot disclosure — add a clear, first-contact notice to any AI that talks to users ('You're chatting with an AI assistant'), placed so a reasonable person could not miss it. Cover voice as well as text.
- Synthetic-media marking and labels — for anything your product generates, enable the provider's machine-readable marking (watermark / content credentials) and add a visible 'AI-generated' label where a person will see the output. Keep the deepfake and public-interest-text carve-outs in mind for editorial contexts.
- A labelling policy — a short internal document that lists which of your systems interact with people or generate content, states how each disclosure or mark is applied, names the owner of the disclosure copy, and sets a review date. This is the artefact a regulator or customer will actually ask to see.
The point of writing it down is that transparency duties are easy to satisfy on day one and easy to let drift — a redesign quietly drops the chatbot banner, or a new feature starts generating images without a label. A living policy that is reviewed is what keeps you compliant, rather than compliant-once.
Where Veritome fits
Veritome's engine surfaces the Article 50 obligations automatically from how a system is described: flag a system as a chatbot and it raises the 50(1) interaction-disclosure duty; flag it as generating content and it raises the 50(2) marking duty; flag deepfake or emotion-recognition use and it raises the 50(3) and 50(4) duties, with the editorial and artistic carve-outs noted where they apply. Each obligation becomes a tracked item with an owner, evidence and a review date, so the disclosures stay in place through redesigns rather than being a launch-day checkbox.
This article is general information about the EU AI Act and how Article 50 works — it is not legal advice. For how these transparency duties apply to a specific product, especially the editorial and artistic carve-outs, take qualified advice.